← All CVEs

CVE-2019-5108

medium · 6.5

An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby APs of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.

6.5
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2019-12-23
Published

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-440CWE-287

Affected products

VendorProductAffected versions
linuxlinux_kernel< 5.3
debiandebian_linux8.0
debiandebian_linux9.0
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
netappactive_iq_unified_managerall versions
netappcloud_backupall versions
netappdata_availability_servicesall versions
netappe-series_santricity_os_controller>= 11.0.0, <= 11.70.1
netapphci_management_nodeall versions
netappsolidfireall versions
netappsteelstore_cloud_integrated_storageall versions
netappa700s_firmwareall versions
netappa700sall versions
netapph610s_firmwareall versions
netapph610sall versions
netapp8300_firmwareall versions
netapp8300all versions
netapp8700_firmwareall versions
netapp8700all versions
netappa400_firmwareall versions
netappa400all versions
oraclesd-wan_edge8.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-5108